The Role
Lead RMF activities for DoD systems including SSP, RAR, POA&M development and maintenance; manage eMASS/ITIPS authorization data; perform vulnerability assessments, risk analyses, and remediation coordination; prepare AO decision packages, POA&M reports, system inventories, and brief leadership; review subordinate RMF artifacts and participate in governance.
Summary Generated by Built In
We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward thinking candidates that have strong experience in operational support and can help take to the next level in a pro-active stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U. S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid Life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
SENIOR CYBERSECURITY ANALYST / RMF LEAD
Position mission: Lead the hands-on development, review, and maintenance of RMF and authorization work products across the DAF FM system portfolio.
Duties:
- Lead RMF activities from control selection through authorization and continuous monitoring.
- Develop and maintain SSPs, RARs, POA&Ms, control implementation records, and supporting evidence.
- Maintain authorization information in eMASS and ITIPS.
- Review security-control assessment results and develop risk-based remediation recommendations.
- Conduct vulnerability assessments and risk analyses.
- Coordinate vulnerability remediation with system owners and program offices.
- Analyze vulnerability and POA&M trends across multiple systems.
- Prepare complete AO decision staff packages containing risk analysis, control summaries, mission impact, and a formal authorization recommendation.
- Prepare monthly POA&M status reports and high-risk escalation reports.
- Maintain FM system inventories, boundaries, authorization status, points of contact, and ATO expiration data.
- Brief leadership and participate in governance forums.
- Review subordinate RMF work products for accuracy, traceability, and readiness for Government review.
MANDATORY COMPLIANCE REQUIREMENT (DoD 8570/8140):
To be considered for this role, candidates must meet ONE of the following qualification pathways:
- DoD 5870 IAM Level III: Hold an active high-tier management certification (CISSP, CISM, or GSLC).OR
- Dod 8140 Work Role 722-Advanced: Hold a relevant degree (Master's or Bachelor's in Cybersecurity, IT, or Computer Science) combined with documented on-the-job experience performing RMF, eMASS, or cybersecurity governance activities
- Direct authorship or lead review of authorization packages.
- eMASS and ITIPS entries personally developed or maintained.
- Examples of ATO, conditional ATO, reauthorization, or denial recommendations.
- SSP, RAR, POA&M, assessment, and continuous-monitoring experience.
- Multi-system vulnerability and remediation tracking.
- Technical interpretation of federal, DoD, or Air Force cybersecurity policy.
- Leadership briefings and formal risk recommendations.
- Coordination with system owners, engineers, assessors, and authorization officials.
Anticipated start: September 28, 2026
Primary work location: Ellsworth AFB, South Dakota. Occasional work at Wright-Patterson AFB, Ohio.
Work schedule: An eight-hour shift scheduled between 6:00 a.m. and 6:00 p.m. Mountain Time, Monday through Friday. The team must collectively provide overlapping coverage during that window. COOP support may be required, but work will remain within a 40-hour workweek unless the Contracting Officer authorizes otherwise.
Project Length: Up to 4.5 years
Skills Required
- DoD 8570 IAM Level III certification
- DoD 8140 work role 722-Advanced
- Hands-on RMF experience leading control selection through authorization and continuous monitoring
- Develop and maintain SSPs, RARs, POA&Ms, control implementation records, and supporting evidence
- Experience using eMASS and ITIPS to maintain authorization information
- Conduct vulnerability assessments and risk analyses and coordinate remediation with system owners
- Prepare AO decision packages, monthly POA&M status reports, and high-risk escalation reports
- Brief leadership and participate in governance forums; review RMF work products for accuracy and traceability
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Chameleon Integrated Services is an information technology company offering requirements management services.






